Before Fraud Reaches the Courtroom: Why Lawyers Must Help Build Fraud-Resilient Organisations?

By Mathuraiveran “Madhu” Marimuthu

Governance, Risk and Internal Control Specialist | Past President, Institute of Internal Auditors Malaysia

By the time a major corporate fraud reaches the courtroom, much of the damage has already occurred.

Money may have disappeared. Records may have been altered. Employees may have lost their jobs. Shareholders may have suffered. Reputations built over decades may have collapsed within days.

Lawyers then become central to the response. They advise directors, preserve privilege, manage regulatory exposure, assess contractual rights, coordinate investigations and prepare for litigation or enforcement action.

But an important question deserves greater attention:

Where were the lawyers before the fraud occurred?

This is not a criticism of the legal profession. It is an invitation to expand its contribution.

After more than 35 years working in internal audit, governance, fraud risk and board oversight, I have come to believe that the legal profession has a crucial preventive role. Lawyers should not be viewed only as professionals who interpret the consequences of organisational failure. They can help design the governance arrangements that make failure less likely.

Fraud is undoubtedly a legal issue. But before it becomes a legal case, it is usually a governance problem.

Fraud Begins in the Space Between Law and Practice

Most organisations affected by fraud are not completely without policies.

They may have codes of conduct, procurement procedures, delegated authority limits, whistleblowing policies, conflict-of-interest declarations and anti-bribery commitments.

The difficulty is that documents do not govern organisations. People do.

Fraud develops in the space between what a policy says and what leaders permit. It grows when exceptions become routine, when senior officers bypass procedures, when commercial pressure overwhelms ethical judgment and when employees learn that challenging authority is professionally dangerous.

In my work with boards, Audit Committees, management teams and internal auditors, I have repeatedly observed that serious control failures rarely begin with a dramatic criminal act.

They begin with a small compromise.

A supporting document is not obtained because the transaction is urgent. A related-party connection is not disclosed because “everyone knows about it.” A tender requirement is waived because the vendor is trusted. An executive instructs an employee to process a transaction first and regularize it later.

Each decision may appear manageable in isolation.

Over time, however, exceptions create a parallel system—one governed not by policy, but by influence and power.

This is where legal education must move beyond explaining what the law prohibits. Future lawyers must learn to recognize the organisational conditions in which illegality becomes possible.

Directors’ Duties Are Active Responsibilities

Malaysia’s Companies Act 2016 requires directors to exercise their powers for a proper purpose, in good faith and in the company’s best interests. Directors are also expected to exercise reasonable care, skill and diligence.

These are not passive duties.

A director cannot discharge responsibility merely by attending meetings, receiving papers and accepting management explanations. Effective oversight requires informed questioning, independent assessment and appropriate follow-through.

This becomes particularly important when the warning signs involve senior management.

Many organisations design controls on the assumption that misconduct will be committed by junior or operational employees. Yet some of the most damaging corporate failures involve management override, collusion and the use of legitimate authority for improper purposes.

A senior executive does not necessarily need to break into a system. The executive may already possess the authority to approve, instruct, appoint, transfer or suppress.

For directors, the critical governance question is therefore not only, “Do we have controls?”

It is also:
Legal advisers can help boards translate statutory duties into practical governance expectations.

Corporate Liability Has Changed the Conversation

Section 17A of the Malaysian Anti-Corruption Commission Act 2009 introduced corporate liability where an associated person corruptly gives, agrees to give, promises or offers gratification for the benefit of a commercial organisation. The framework also places considerable importance on whether the organisation had adequate procedures designed to prevent such conduct.

This should change the way lawyers advise organisations.

The central question is no longer simply whether senior management authorised the corrupt payment.

Organisations must consider the conduct of employees, agents, intermediaries, contractors and other associated persons. This makes third-party governance legally and strategically important.

A contract containing an anti-bribery clause is useful. But a clause alone does not establish an effective anti-corruption system.

Organisations should be able to demonstrate how they:

Adequate procedures must exist in operation, not merely in a compliance manual.

Lawyers are well placed to ensure that anti-corruption frameworks are legally sound. They should also work with risk, compliance, procurement, internal audit, human resources and technology professionals to ensure those frameworks are practically effective.

Whistleblowing Is a Test of Institutional Justice

The ACFE’s 2026 global study found that 43% of occupational fraud cases were detected following a tip, with more than half of those tips coming from employees.

That finding carries an important legal and governance lesson: the people closest to wrongdoing are often the first to recognise it.

But employees will not speak merely because a hotline exists.

They assess whether the process is trustworthy. They ask themselves:

Malaysia’s Whistleblower Protection Act 2010 provides a statutory framework for disclosures and protections, while official guidance and public-sector policies recognise protections relating to confidentiality, immunity and detrimental action in qualifying circumstances.

However, statutory protection and organisational trust are not identical.

A legally compliant reporting mechanism may still fail if employees believe senior people are untouchable.

Lawyers involved in designing whistleblowing frameworks should therefore think beyond procedural compliance. They must consider fairness, independence, conflicts, retaliation risks, evidence handling and the rights of both the whistleblower and the person accused.

A credible process must protect the reporter without presuming the allegation is true.

That balance is one of the most important contributions lawyers can make.

Deepfakes and the Coming Evidential Challenge

The emergence of generative AI adds another dimension to fraud law.

Audio, video, correspondence and documents can now be fabricated with increasing sophistication. Fraudsters may impersonate executives, create synthetic identities, alter digital evidence or produce false narratives supported by apparently convincing media.

In July 2026, the FBI described ongoing schemes involving AI-generated videos, spoofed websites and impersonation of government personnel.

This raises difficult questions for lawyers:

Legal education must prepare students for a world in which evidence may be technically convincing but factually false.

Tomorrow’s commercial and criminal lawyers will need a working understanding of digital forensics, cybersecurity, data governance and AI assurance. They will not need to become software engineers, but they must know enough to ask the right questions of technical specialists.

The Lawyer as Governance Architect

A future-ready corporate lawyer should be more than a drafter of documents or interpreter of statutes.

The lawyer should help establish clarity around:

The Malaysian Code on Corporate Governance places board leadership alongside effective audit, risk management and internal controls as central features of corporate governance.

This reinforces an important principle: compliance cannot be separated from governance.

The legal department should not become solely responsible for fraud risk, just as internal audit should not own the organisation’s controls. Fraud risk is a shared organisational responsibility.

However, lawyers can become the connectors who help ensure that legal obligations, governance expectations and operational practices are aligned.

What Law Schools Should Do

Law schools can prepare students for this expanded role through experiential and interdisciplinary learning.

Students should examine fraud cases not only by identifying offences and possible defences, but by reconstructing the organisational breakdown.

They should ask:

Law students could work alongside students of technology, accounting and psychology in simulated investigations. They could advise a fictional board responding to a whistleblower allegation, assess a third-party corruption risk or determine how to preserve evidence after a deepfake payment fraud.

Such exercises would teach students that fraud cases are rarely confined to one legal category. They may involve company law, employment law, evidence, privacy, contract, anti-corruption law, regulatory obligations and directors’ duties simultaneously.

Leadership Is the Final Control

Throughout my career, I have examined many control systems.

Some were sophisticated. Others were basic. But the most decisive variable was often the behaviour of leadership.

When leaders respect controls, disclose their own conflicts and welcome challenge, employees learn that integrity matters.

When leaders create exceptions for themselves, employees learn that rules are negotiable.

The law establishes minimum expectations. Governance determines whether those expectations become part of organisational life.

Lawyers have an important choice.

They can remain professionals who are called after the damage has been done, or they can become trusted advisers who help organisations recognise risk before misconduct becomes a scandal.

The future of legal practice lies not only in resolving disputes.

It also lies in helping institutions remain worthy of trust.

About the Author

Mathuraiveran “Madhu” Marimuthu is a governance, risk and internal control specialist with more than 35 years of experience in internal audit, fraud risk management, corporate governance and board oversight. A Chartered Accountant and Past President of the Institute of Internal Auditors Malaysia, he served for approximately 20 years on the institute’s board and has served on corporate boards and Audit Committees. He is a corporate trainer and the developer of a practical Fraud Detection and Prevention Toolkit.